State Agency Website
https://atg.sd.gov/
Timing of Consumer Notification
“Within 60 days of discovery of the breach.”
Method of Notice
Mail. Email permitted if complies with E-SIGN.
Breach Definition
Unauthorized acquisition of unencrypted computerized data, or encrypted computerized data and encryption key, that materially compromises security, confidentiality, or integrity of personal or protected information.
PII Definition
Individual’s first name or first initial and last name, in combination with any one or more of the following:
  1. Social Security number;
  2. Driver’s license number or other unique identification number created or collected by government body;
  3. Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or any additional information that would permit access to account;
  4. Health information as defined in 45 CFR 160.103; or
  5. Identification number assigned by employer in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication purposes.
“Protected information” does not require the below to be used in combination with person’s name. Includes:
  1. User name or email address, in combination with password, security question answer, or other information that permits access to online account; and
  2. Account number or credit or debit card number, in combination with any required security code, access code, or password that permits access to person's financial account
Third Party Notice
None.
How to Notify
No specific content requirement.
Substitute Notice
(a) Email notice, if entity has email address for affected individuals; (b) conspicuous posting on entity’s website, if it maintains one; and (c) notification to statewide media.
Credit Monitoring
Not required.
When to Notify Credit Agencies
Without unreasonable delay, of timing, distribution, and content of notice to affected individuals.
This State's Law
Includes notification requirements for defined “protected information” (see above) as well as defined “personal information” (see above).
State Government Agency Notification Required
Yes, South Dakota Attorney General must be notified if more than 250 SD residents must be notified.